Create a bot route rule
const url = 'https://api.nsin.ir/domains/example.com/rules/bot-route/';const options = { method: 'POST', headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'}, body: '{"record_id":1,"record_ids":[1],"enabled":true,"priority":100,"host_pattern":"example","host_match_type":"","action_mode":"enforce","bot_kinds":["*"],"require_verified":true,"action":"block","status":200,"body":"example","alt_dest":"example","alt_port":1,"alt_scheme":"http"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url https://api.nsin.ir/domains/example.com/rules/bot-route/ \ --header 'Authorization: Bearer <token>' \ --header 'Content-Type: application/json' \ --data '{ "record_id": 1, "record_ids": [ 1 ], "enabled": true, "priority": 100, "host_pattern": "example", "host_match_type": "", "action_mode": "enforce", "bot_kinds": [ "*" ], "require_verified": true, "action": "block", "status": 200, "body": "example", "alt_dest": "example", "alt_port": 1, "alt_scheme": "http" }'Acts on classified bot traffic — block it, serve alternative content, send it to a different origin, or just tag it in telemetry.
Requires rules.edit.
Authorizations
Section titled “Authorizations ”Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters ”The domain name (for example example.com) — not a numeric id.
Example
example.comRequest Body required
Section titled “Request Body required ”object
Deprecated single-record scope. Prefer record_ids.
Scope the rule to these proxied records. Omit or send an empty array for a zone-wide rule. Every id must belong to this domain.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
Which bots this rule matches. Must not be empty.
Only match bots whose identity was verified (by reverse DNS or published IP ranges), not merely self-declared in the user agent.
block— refuse the request.alt_content— servebodywithstatusinstead of the origin.alt_origin— proxy toalt_dest:alt_portoveralt_scheme.tag— let it through, but tag it in telemetry.
Status code for alt_content.
Response body for alt_content.
Origin address for alt_origin.
Origin port for alt_origin.
Scheme used to reach alt_dest.
Responses
Section titled “ Responses ”Rule created.
object
Deprecated single-record scope. Prefer record_ids. Absent for
zone-wide rules.
The proxied DNS records this rule applies to. Empty or absent means zone-wide — every proxied record of the domain.
Evaluation order; lower runs first. Defaults to 100.
Optional hostname filter. Empty means the rule is not host-scoped.
How host_pattern is matched. The empty string means “no host filter”,
and is the only valid value when host_pattern is empty — the two
fields are set and cleared together.
enforce— the rule acts (block, redirect, challenge, …).dry_run— the rule matches and is logged as “would have acted”, but the request reaches the origin unchanged. Use it to test a rule safely.
Not every rule type honours this; cache ignores it.
Which bots this rule matches. Must not be empty.
Only match bots whose identity was verified (by reverse DNS or published IP ranges), not merely self-declared in the user agent.
block— refuse the request.alt_content— servebodywithstatusinstead of the origin.alt_origin— proxy toalt_dest:alt_portoveralt_scheme.tag— let it through, but tag it in telemetry.
Status code for alt_content.
Response body for alt_content.
Origin address for alt_origin.
Origin port for alt_origin.
Scheme used to reach alt_dest.
Example
{ "type": "cache", "host_match_type": "", "action_mode": "enforce", "bot_kinds": [ "*" ], "action": "block", "status": 200, "alt_scheme": "http"}Malformed body, an invalid field value, or record_ids containing a
record that does not belong to this domain.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "record_ids do not belong to this domain"}Missing, malformed, revoked or expired API key — or the owning account is inactive.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "invalid API key"}The key is read-only, or the domain’s plan does not include this rule type or allows fewer rules of it than you already have.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Example
{ "error": "read-only API key"}No such domain, or your role on it does not permit this operation. The
rules endpoints deliberately answer 404 rather than 403 for an
insufficient role, so they never confirm that a domain exists to someone
who cannot use it.
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "not found"}The key exceeded its request budget (300 requests per minute by default).
The single error shape used by every endpoint.
object
Human-readable description of what went wrong.
Examples
{ "error": "rate limit exceeded"}